HomeSecuritySysBumps attack bypasses macOS system security

SysBumps attack bypasses macOS system security

Security researchers have discovered a new attack targeting macOS systems running on Apple Silicon. Dubbed “SysBumps,” this attack exploits speculative execution vulnerabilities in system calls to bypass kernel isolation and disrupt kernel address space layout randomization (KASLR), a critical security feature.

See also: New NotLockBit ransomware targets Windows and macOS

SysBumps macOS

The research team from Korea University, led by Hyerean Jang, Taehun Kim, and Youngjoo Shin, presented their findings in a paper titled "SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon."

Their work represents the first successful KASLR break attack on macOS systems powered by Apple's custom ARM-based chips .

KASLR is a defense mechanism that randomizes the layout of kernel memory, making it more difficult for attackers to predict the location of specific functions or data structures. By violating KASLR, malicious actors can potentially exploit other vulnerabilities more easily, compromising the security of the system.

See also: New Meeten malware targets macOS and Windows users

The SysBumps attack exploits speculative execution, a performance optimization technique used in modern processors.

SysBumps attack bypasses macOS system security

By exploiting Spectre -like vulnerabilities in certain macOS system calls, researchers demonstrated that an unprivileged attacker could cause transient memory accesses to kernel addresses, even with kernel isolation enabled.

A key element of the attack involves using the Translation Lookaside Buffer (TLB) as a side channel to extract information about the kernel's memory layout. The research team reshaped the TLB structure of several M-series processors, revealing previously unknown details about its architecture.

The SysBumps attack works by constructing a token oracle that can determine whether a given kernel address is valid or not. This allows attackers to gradually map the memory space and eventually determine its base address, effectively breaking KASLR.

See also: MacOS faces AI-Powered Malware attacks

A Kernel Break attack is an advanced method of exploiting vulnerabilities at the core level of an operating system. This type of attack involves targeting the kernel, which serves as a bridge between software applications and hardware. By compromising the kernel, attackers can gain privileged access to the system, bypassing standard security mechanisms. Kernel Break attacks often involve exploiting zero-day vulnerabilities or unsafe system calls, which makes them particularly difficult to detect and prevent. Implementing strong security measures, such as kernel-level integrity checks and timely system updates, are critical to defending against these sophisticated threats.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS